Los Angeles-based UCLA Health disclosed a data breach involving patient information that was inconsistent with the health system’s privacy policies governing protected health information.
UCLA Health discovered the activity on July 2, and took steps to stop it while launching an investigation. In some instances, patient information was also disclosed to an outside healthcare provider, according to an Aug. 3 news release from the health system.
The information involved varies by individual and may include patient names, addresses, dates of birth and health insurance information, along with clinical information such as referral orders. For some individuals, the last four digits of a Social Security number were also affected.
UCLA Health said no full Social Security numbers, financial account numbers or payment card information were involved.
The health system has not identified evidence that the information was further disclosed or misused. UCLA Health said it has reviewed its administrative and technical safeguards and is implementing additional measures to strengthen oversight of access to protected health information.